<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5769-1 false positives in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537546#M94848</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had to re-attach file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Jun 2006 11:26:34 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2006-06-16T11:26:34Z</dc:date>
    <item>
      <title>5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537542#M94844</link>
      <description>&lt;P&gt;This signature triggers on multipart/form-data POST argument values containing valid HTTP methods (GET,POST,DELETE,etc).  This happens suprisingly often on the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1147308732612292092  vendor=Cisco  severity=medium  &lt;/P&gt;&lt;P&gt;  originator:   &lt;/P&gt;&lt;P&gt;    hostId: 88-nsmc-c1  &lt;/P&gt;&lt;P&gt;    appName: sensorApp  &lt;/P&gt;&lt;P&gt;    appInstanceId: 12786  &lt;/P&gt;&lt;P&gt;  time: June 15, 2006 8:09:04 PM UTC  offset=-300  timeZone=GMT-06:00  &lt;/P&gt;&lt;P&gt;  signature:   description=Malformed HTTP Request  id=5769  version=S231  &lt;/P&gt;&lt;P&gt;    subsigId: 1  &lt;/P&gt;&lt;P&gt;    sigDetails: Malformed HTTP Request  &lt;/P&gt;&lt;P&gt;  interfaceGroup:   &lt;/P&gt;&lt;P&gt;  vlan: 0  &lt;/P&gt;&lt;P&gt;  participants:   &lt;/P&gt;&lt;P&gt;    attacker:   &lt;/P&gt;&lt;P&gt;      addr: 162.131.154.58  locality=NETCACHE  &lt;/P&gt;&lt;P&gt;      port: 60736  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 162.131.88.12  locality=INTERNAL  &lt;/P&gt;&lt;P&gt;      port: 80  &lt;/P&gt;&lt;P&gt;  context:   &lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;000000  6E 74 65 6E 74 2D 44 69  73 70 6F 73 69 74 69 6F  ntent-Dispositio&lt;/P&gt;&lt;P&gt;000010  6E 3A 20 66 6F 72 6D 2D  64 61 74 61 3B 20 6E 61  n: form-data; na&lt;/P&gt;&lt;P&gt;000020  6D 65 3D 22 70 6F 73 74  69 64 22 0D 0A 0D 0A 31  me="postid"....1&lt;/P&gt;&lt;P&gt;000030  31 35 30 34 30 31 32 37  31 0D 0A 2D 2D 2D 2D 2D  150401271..-----&lt;/P&gt;&lt;P&gt;000040  2D 2D 2D 2D 2D 2D 2D 2D  2D 2D 2D 2D 2D 2D 2D 2D  ----------------&lt;/P&gt;&lt;P&gt;000050  2D 2D 2D 2D 2D 2D 2D 2D  32 31 30 30 38 33 32 38  --------21008328&lt;/P&gt;&lt;P&gt;000060  38 35 39 38 0D 0A 43 6F  6E 74 65 6E 74 2D 44 69  8598..Content-Di&lt;/P&gt;&lt;P&gt;000070  73 70 6F 73 69 74 69 6F  6E 3A 20 66 6F 72 6D 2D  sposition: form-&lt;/P&gt;&lt;P&gt;000080  64 61 74 61 3B 20 6E 61  6D 65 3D 22 74 79 70 65  data; name="type&lt;/P&gt;&lt;P&gt;000090  22 0D 0A 0D 0A 53 74 61  6E 64 61 72 64 0D 0A 2D  "....Standard..-&lt;/P&gt;&lt;P&gt;0000A0  2D 2D 2D 2D 2D 2D 2D 2D  2D 2D 2D 2D 2D 2D 2D 2D  ----------------&lt;/P&gt;&lt;P&gt;0000B0  2D 2D 2D 2D 2D 2D 2D 2D  2D 2D 2D 2D 32 31 30 30  ------------2100&lt;/P&gt;&lt;P&gt;0000C0  38 33 32 38 38 35 39 38  0D 0A 43 6F 6E 74 65 6E  83288598..Conten&lt;/P&gt;&lt;P&gt;0000D0  74 2D 44 69 73 70 6F 73  69 74 69 6F 6E 3A 20 66  t-Disposition: f&lt;/P&gt;&lt;P&gt;0000E0  6F 72 6D 2D 64 61 74 61  3B 20 6E 61 6D 65 3D 22  orm-data; name="&lt;/P&gt;&lt;P&gt;0000F0  73 75 6D 6D 61 72 79 22  0D 0A 0D 0A 50 6F 73 74  summary"....Post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  riskRatingValue: 51  &lt;/P&gt;&lt;P&gt;  interface: ge0_1  &lt;/P&gt;&lt;P&gt;  protocol: tcp  &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537542#M94844</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2019-03-10T10:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537543#M94845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are actively working on this. Unfortunately, the alert above does not give us the complete information needed to idenfity the problem with the signature. If you could send us a traffic sample, that would be very helpful to us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Radhika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jun 2006 23:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537543#M94845</guid>
      <dc:creator>rupadras</dc:creator>
      <dc:date>2006-06-15T23:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537544#M94846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't believe I have a trace (I'll verify tomorrow), but I can get one easy enough.  The act of adding an attachment to a post in one of these forums with a keyword of "Post" (or Get or Delete, etc) should trigger it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2006 02:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537544#M94846</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-06-16T02:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537545#M94847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The attached pcap file contains the relevant post which triggered this alarm:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1136142973381638834  vendor=Cisco  severity=medium  &lt;/P&gt;&lt;P&gt;  originator:   &lt;/P&gt;&lt;P&gt;    hostId: 26-fw-dmz-c1  &lt;/P&gt;&lt;P&gt;    appName: sensorApp  &lt;/P&gt;&lt;P&gt;    appInstanceId: 13368  &lt;/P&gt;&lt;P&gt;  time: June 16, 2006 12:22:58 PM UTC  offset=-300  timeZone=GMT-06:00  &lt;/P&gt;&lt;P&gt;  signature:   description=Malformed HTTP Request  id=5769  version=S231  &lt;/P&gt;&lt;P&gt;    subsigId: 1  &lt;/P&gt;&lt;P&gt;    sigDetails: Malformed HTTP Request  &lt;/P&gt;&lt;P&gt;  interfaceGroup:   &lt;/P&gt;&lt;P&gt;  vlan: 0  &lt;/P&gt;&lt;P&gt;  participants:   &lt;/P&gt;&lt;P&gt;    attacker:   &lt;/P&gt;&lt;P&gt;      addr: 206.195.195.108  locality=NETCACHE_EXT_IP  &lt;/P&gt;&lt;P&gt;      port: 6884  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 204.69.199.39  locality=ANY  &lt;/P&gt;&lt;P&gt;      port: 80  &lt;/P&gt;&lt;P&gt;  actions:   &lt;/P&gt;&lt;P&gt;    ipLoggingActivated: true  &lt;/P&gt;&lt;P&gt;    logPairPacketsActivated: true  &lt;/P&gt;&lt;P&gt;  context:   &lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;000000  09 00 3C 00 00 00 3C 00  00 00 00 00 5E 00 01 66  ..&amp;lt;...&amp;lt;.....^..f&lt;/P&gt;&lt;P&gt;000010  00 0F 20 6C 99 8B 08 00  45 00 00 28 B3 40 40 00  .. l....E..(.@@.&lt;/P&gt;&lt;P&gt;000020  80 06 21 6A CE C3 C6 74  CE C3 C2 29 01 BB 0D 13  ..!j...t...)....&lt;/P&gt;&lt;P&gt;000030  98 10 06 29 30 48 0F 58  50 04 00 00 9D 13 00 00  ...)0H.XP.......&lt;/P&gt;&lt;P&gt;000040  00 00 00 00 00 00 84 9A  5F 44 E4 C7 09 00 3C 00  ........_D....&amp;lt;.&lt;/P&gt;&lt;P&gt;000050  00 00 3C 00 00 00 00 00  5E 00 01 66 00 0F 20 6C  ..&amp;lt;.....^..f.. l&lt;/P&gt;&lt;P&gt;000060  99 8B 08 00 45 00 00 28  B3 41 00 00 80 06 61 69  ....E..(.A....ai&lt;/P&gt;&lt;P&gt;000070  CE C3 C6 74 CE C3 C2 29  01 BB 0D 13 98 10 06 29  ...t...).......)&lt;/P&gt;&lt;P&gt;000080  98 10 06 29 50 04 00 00  3E 7A 00 00 00 00 00 00  ...)P...&amp;gt;z......&lt;/P&gt;&lt;P&gt;000090  00 00 0D 0A 2D 2D 2D 2D  2D 2D 2D 2D 2D 2D 2D 2D  ....------------&lt;/P&gt;&lt;P&gt;0000A0  2D 2D 2D 2D 2D 2D 2D 2D  2D 2D 2D 2D 2D 2D 2D 2D  ----------------&lt;/P&gt;&lt;P&gt;0000B0  2D 32 34 30 34 33 32 39  37 37 38 32 37 38 31 34  -240432977827814&lt;/P&gt;&lt;P&gt;0000C0  0D 0A 43 6F 6E 74 65 6E  74 2D 44 69 73 70 6F 73  ..Content-Dispos&lt;/P&gt;&lt;P&gt;0000D0  69 74 69 6F 6E 3A 20 66  6F 72 6D 2D 64 61 74 61  ition: form-data&lt;/P&gt;&lt;P&gt;0000E0  3B 20 6E 61 6D 65 3D 22  66 69 6C 65 64 65 73 63  ; name="filedesc&lt;/P&gt;&lt;P&gt;0000F0  72 69 70 74 69 6F 6E 22  0D 0A 0D 0A 50 6F 73 74  ription"....Post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ipLogIds:   &lt;/P&gt;&lt;P&gt;    ipLogId: 1701737422  &lt;/P&gt;&lt;P&gt;  riskRatingValue: 51  &lt;/P&gt;&lt;P&gt;  interface: ge0_0  &lt;/P&gt;&lt;P&gt;  protocol: tcp  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2006 11:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537545#M94847</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-06-16T11:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537546#M94848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had to re-attach file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2006 11:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537546#M94848</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-06-16T11:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537547#M94849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've identified the problem. To resolve this false positive you can add a max inspect length (or max match offset for 5.x users) of 10. This will be resolved in the next signature update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2006 12:55:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537547#M94849</guid>
      <dc:creator>craiwill</dc:creator>
      <dc:date>2006-06-16T12:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537548#M94850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I attempted to apply the fix you had supplied, but ran into something odd.  Can you see if you can explain this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using CS-Manager / IPS manager, I selected to tune the signature in question and found that it was already set at max inspect length of 10.  The drop down menu at the top of the tunning page shows S236 for the signature, but I am only running S232.  I do have auto download configured and do have the S236 signature on the CS-Manager server, but not on my sensor.  Is there anyway to tune the S232 version of the signature in this situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2006 12:03:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537548#M94850</guid>
      <dc:creator>MARK BAKER</dc:creator>
      <dc:date>2006-06-30T12:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537549#M94851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to tune the S231 version of the signature by going to the individual sensors instead of the global group like I had tried to do in the first attempt.  Luckily I only have two sensors to tune.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note:  I would have expected to see all versions of the signature in the drop down menu that shows up for tuning under the global settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2006 12:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537549#M94851</guid>
      <dc:creator>MARK BAKER</dc:creator>
      <dc:date>2006-06-30T12:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: 5769-1 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537550#M94852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could tune it directly on the sensor via IDM. &lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&lt;YOUR-SENSOR-IP&gt;&lt;/YOUR-SENSOR-IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click on "Signature Configuration" under "Signature Definition" on the left hand side TOC. Find the sig in the table then click the edit button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2006 12:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5769-1-false-positives/m-p/537550#M94852</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2006-06-30T12:31:57Z</dc:date>
    </item>
  </channel>
</rss>

